CVE-2026-25035

CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Authentication Abuse.This issue affects ...

Affects 0 products across 3 vendors.

BCS6.33
CVSS 3.19.8
EPSS0.4%
Percentile35th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-288: CWE-288
Related Attack Patterns (CAPEC)
CAPEC-127 Directory Indexing
via CWE-288
CAPEC-665 Exploitation of Thunderbolt Protection Flaws
via CWE-288

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in Contest Gallery, developed by Wasiliy Strecker / ContestGallery developer Co, allows attackers to bypass authentication through an alternate path or channel. This issue affects versions up to and including 28.1.2.2.

BSID: BS-2026-GLOBAL-073129-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-25035?
A critical vulnerability in Contest Gallery, developed by Wasiliy Strecker / ContestGallery developer Co, allows attackers to bypass authentication through an alternate path or channel. This issue affects versions up to and including 28.1.2.2.
What is the CVSS score for CVE-2026-25035?
CVE-2026-25035 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.4%.
Is CVE-2026-25035 actively exploited?
No confirmed active exploitation of CVE-2026-25035 as of 2026-05-30.
How do I remediate CVE-2026-25035?
Priority: IMMEDIATE.
What systems are affected by CVE-2026-25035?
CVE-2026-25035 affects: Abuse, Contest-Gallery, Gallery.
Vulnerability Details
CVE IDCVE-2026-25035
BSIDBS-2026-GLOBAL-073129-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2026-03-25
Last Modified2026-04-24
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Authentication Abuse.This issue affects Contest Gallery: from n/a through <= 28.1.2.2.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability arises from an improper handling of authentication processes, enabling attackers to exploit an alternate path or channel to gain unauthorized access without proper credentials.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Abuse &mdash;
Contest-Gallery &mdash;
Gallery &mdash;
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 151 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash320b0e94c4ddd65f3afe0ddbaa38deec0bd6d02ffdd0ea1964eecd00154fcafe4e2cba22cf62aeef4c946d9e849de89706ba16b5cb9db34a17b25b5096a024a5
Related CVEs affecting Abuse
CVE-1999-0512 10.0 A mail server is explicitly configured to allow SMTP mail relay, which allows... CVE-2026-23693 10.0 ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elemen... CVE-2025-4378 10.0 Cleartext Transmission of Sensitive Information, Use of Hard-coded Credential... CVE-2024-28189 10.0 Judge0 is an open-source online code execution system. The application uses t... CVE-2026-40089 9.9 Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. Th...
View all Abuse CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →